mistyree Posted December 20, 2008 Report Share Posted December 20, 2008 i had been using 1.77 with no problems this whole year.i just updated to 1.81 and it keeps freezing up my whole computer.i cannot get out by any other way except by hitting the actual turn on button (reset?) to my pc which i do know that is not good.does anyone know why this new utorrent is doing this?i love utorrent and am so disappointed in myself for not leaving it where it was on the 1.77can i just switch it back?or is it too late now that i switched to 1.81?thanks Link to comment Share on other sites More sharing options...
moogly Posted December 20, 2008 Report Share Posted December 20, 2008 Downgrading is not a good tip because of security holes in 1.7.7.Post HJT & PE logs (copy/paste here) to see what is injected in uT.Tutorial: http://forum.utorrent.com/viewtopic.php?id=29748DONT FORGET to select utorrent.exe & enable DLL mode (ctrl+d) in PE Link to comment Share on other sites More sharing options...
mistyree Posted December 20, 2008 Author Report Share Posted December 20, 2008 thankyou for your fast responsei have never heard of the process explorer and do not use iti honestly had no problems until i switched to 1.81it was automatic so i know it IS definitely relatedhere is my log below i hope u can help meLogfile of Trend Micro HijackThis v2.0.2Scan saved at 11:35:21 PM, on 12/19/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16762)Boot mode: NormalRunning processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Spyware Terminator\SpywareTerminatorShield.exeC:\WINNT\system32\cisvc.exeC:\WINNT\system32\lxdvcoms.exeC:\Program Files\Spyware Terminator\sp_rsser.exeC:\WINNT\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\wuauclt.exeC:\WINNT\system32\cidaemon.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Opera\Opera.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.roadrunner.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.roadrunner.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dllO3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dllO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKLM\..\Run: [igfxTray] C:\WINNT\System32\igfxtray.exeO4 - HKLM\..\Run: [spywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"O8 - Extra context menu item: Crawler Search - tbr:iemenuO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dllO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141061328921O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1141933819203O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dllO18 - Filter hijack: text/html - (no CLSID) - (no file)O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - Unknown owner - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (file missing)O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)O23 - Service: lxdvCATSCustConnectService - Lexmark International, Inc. - C:\WINNT\System32\spool\DRIVERS\W32X86\3\\lxdvserv.exeO23 - Service: lxdv_device - - C:\WINNT\system32\lxdvcoms.exeO23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exeO23 - Service: Retrospect Launcher (RetroLauncher) - Unknown owner - G:\Retrospect 7.6\retrorun.exe (file missing)O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exeO23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINNT\System32\TuneUpDefragService.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe--End of file - 5415 bytes Link to comment Share on other sites More sharing options...
thelittlefire Posted December 20, 2008 Report Share Posted December 20, 2008 Try without Zone Alarm. Then Spyware Terminator. Then . . .avast try bypassing the web monitor for utorrent.exe Link to comment Share on other sites More sharing options...
mistyree Posted December 20, 2008 Author Report Share Posted December 20, 2008 will i be without protection if i run witohut these programs? Link to comment Share on other sites More sharing options...
moogly Posted December 20, 2008 Report Share Posted December 20, 2008 Surely ZA, very buggy. Try another firewal like Comodo.http://www.matousec.com/projects/firewall-challenge/results.php#firewalls-ratingsYou can try to disable your anti-spyware before ZA and see if uT works. Link to comment Share on other sites More sharing options...
mistyree Posted December 21, 2008 Author Report Share Posted December 21, 2008 i went to comodo to dl but it says my choices for use is 32 bit vista or 64 bit vista and i have winxpi have included link to showhttp://www.personalfirewall.comodo.com/download_firewall.htmlalso doesnt matter what i disable utorrent still having problems Link to comment Share on other sites More sharing options...
moogly Posted December 21, 2008 Report Share Posted December 21, 2008 XP (SP2) / Vista 32 bit : same dwl. Link to comment Share on other sites More sharing options...
mistyree Posted December 23, 2008 Author Report Share Posted December 23, 2008 lol-thankyou - blonde moment here im going to try this now with the utorrent and respond with results Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.